First published: Tue Nov 18 2008(Updated: )
mail2sms.sh in smsclient 2.0.8z allows local users to overwrite arbitrary files via a symlink attack on a (1) /tmp/header.##### or (2) /tmp/body.##### temporary file, or append data to arbitrary files via a symlink attack on the (3) /tmp/sms.log temporary file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Smsclient | =2.0.8z |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-5155 is considered to be moderate in severity due to its potential for local file overwrite and data manipulation.
To fix CVE-2008-5155, upgrade to a newer version of smsclient that does not utilize temporary files in a vulnerable manner.
Local users on systems running smsclient version 2.0.8z are affected by CVE-2008-5155.
CVE-2008-5155 allows for symlink attacks that can overwrite arbitrary files or append data to unintended files.
The temporary files involved in CVE-2008-5155 include /tmp/header.#####, /tmp/body.#####, and /tmp/sms.log.